CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows

Cli ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions 1.0.0 through 1.0.212 (Kiro IDE), prior to v2.10.0 (Kiro CLI)
Regions all
CVE IDs CVE-2026-18656, CVE-2026-18657
Migration Required Yes
Cost Impact Neutral

What This Means

For DevOps Teams

Update Kiro IDE to version 1.0.228 and Kiro CLI to version 2.10.0 to address security vulnerabilities CVE-2026-18656 and CVE-2026-18657, ensuring no workarounds are available and immediate action is required to prevent potential code execution from untrusted directories.

For Platform Teams

Deploy the latest versions of Kiro IDE and CLI to incorporate critical security patches for vulnerabilities CVE-2026-18656 and CVE-2026-18657, enhancing platform security and reducing risk of arbitrary code execution from untrusted project directories.

For Executives

Implement immediate upgrade to Kiro IDE version 1.0.228 and Kiro CLI version 2.10.0 to mitigate security vulnerabilities CVE-2026-18656 and CVE-2026-18657, ensuring protection against arbitrary code execution from untrusted project directories on Windows.

Source

View original AWS announcement โ†’

Related Cli Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.